Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com |
| Categories | Security - Threat Protection |
| Version | 3.0.3 |
| Author | 42Crunch - plugins@42crunch.com |
| First Published | 2022-09-21 |
| Last Updated | 2026-07-29 |
| Solution Folder | 42Crunch API Protection |
| Marketplace | Azure Marketplace · Popularity: 🟡 Low (28%) |
The 42Crunch API Protection solution protects APIs by installing a microfirewall inline with the API server. Access logs from the microfirewall are emitted to Microsoft Sentinel allowing analysis and investigation of attacks.
This solution provides 2 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 2 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
FortyTwoCrunchAPIProtectionV2_CL |
42Crunch API Protection (Push Connector via Codeless Connector Framework) | Analytics, Workbooks |
apifirewall_log_1_CL 🔶 |
API Protection | Analytics, Workbooks |
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 13 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 11 |
| Workbooks | 1 |
| Parsers | 1 |
| Name | Tables Used |
|---|---|
| 42CrunchAPIProtectionWorkbook | FortyTwoCrunchAPIProtectionV2_CLapifirewall_log_1_CL |
| Name | Description | Tables Used |
|---|---|---|
| FortyTwoCrunchAPIProtection | - | FortyTwoCrunchAPIProtectionV2_CL (read)apifirewall_log_1_CL (read) |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.3 | 27-07-2026 | Promoted the connector to GA Renamed CCF Push Data Connector files (ConnectorDefinition, DCR, PollerConfig) in the 42Crunch_CCF folder to follow the standard CCF naming convention. Added Parser alias function (FortyTwoCrunchAPIProtectionV2) for the V2 table. |
| 3.0.2 | 15-07-2026 | Update publisher and support information in SolutionMetadata.json |
| 3.0.1 | 25-05-2026 | Added CCF Push Data Connector (OAuth2/Entra ID via DCE/DCR) alongside legacy connector; added backward-compatible Parser (FortyTwoCrunchAPIProtection) supporting both apifirewall_log_1_CL and FortyTwoCrunchAPIProtectionV2_CL schemas. Updated all 11 Analytic Rules to use the parser alias and PascalCase column names, added Migration Guide with end-to-end validated ccf-forwarder sample deployment, and refreshed Workbook metadata. |
| 3.0.0 | 15-07-2024 | Missing Tactics and Techniques added |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊